pg.ddx.io  pgsql-sql@postgresql.org mailing list archive  
help / color / mirror / Atom feed
Reading from file without superuser privilege
2+ messages / 2 participants
[nested] [flat]

* Reading from file without superuser privilege
@ 2013-03-21 11:43 Jose Antonio Quintana/UPC <jose.antonio.quintana@upc.edu>
  2013-03-21 13:40 ` Re: Reading from file without superuser privilege Adrian Klaver <adrian.klaver@gmail.com>
  0 siblings, 1 reply; 2+ messages in thread

From: Jose Antonio Quintana/UPC @ 2013-03-21 11:43 UTC (permalink / raw)
  To: pgsql-sql

I need to read from a file in order to update a table.

The manual says that it is necessary to have the superuser privilege to 
read from a file.

Is it possible to read files without this privilege?

Thanks.


_______________________________________________
José Antonio Quintana Romero
Unitat de Projectes
Vicegerència de Desenvolupament Organitzatiu i Personal
Edifici Vèrtex. Planta 3
Pl. Eusebi Güell, 6 
08034 - Barcelona

^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: Reading from file without superuser privilege
  2013-03-21 11:43 Reading from file without superuser privilege Jose Antonio Quintana/UPC <jose.antonio.quintana@upc.edu>
@ 2013-03-21 13:40 ` Adrian Klaver <adrian.klaver@gmail.com>
  0 siblings, 0 replies; 2+ messages in thread

From: Adrian Klaver @ 2013-03-21 13:40 UTC (permalink / raw)
  To: Jose Antonio Quintana/UPC <jose.antonio.quintana@upc.edu>; +Cc: pgsql-sql

On 03/21/2013 04:43 AM, Jose Antonio Quintana/UPC wrote:
> I need to read from a file in order to update a table.
>
> The manual says that it is necessary to have the superuser privilege to
> read from a file.
>
> Is it possible to read files without this privilege?

What sort of file, any file or one you want to do a COPY or \copy from?

For any file you would need to use one of the untrusted languages, 
plpythonu for example. They need to be installed by a superuser. It is 
possible to create a function in an untrusted language as the superuser 
and then confer the superuser privileges to other users for that 
function by using SECURITY DEFINER, see here:

http://www.postgresql.org/docs/9.2/interactive/sql-createfunction.html

For COPY :
"The file must be accessible to the server and the name must be 
specified from the viewpoint of the server. "


http://www.postgresql.org/docs/9.2/interactive/sql-copy.html

For \copy:
"This is an operation that runs an SQL COPY command, but instead of the 
server reading or writing the specified file, psql reads or writes the 
file and routes the data between the server and the local file system. 
This means that file accessibility and privileges are those of the local 
user, not the server, and no SQL superuser privileges are required."

http://www.postgresql.org/docs/9.2/interactive/app-psql.html

>
> Thanks.
>
>
> _______________________________________________
> José Antonio Quintana Romero
> Unitat de Projectes
> Vicegerència de Desenvolupament Organitzatiu i Personal
> Edifici Vèrtex. Planta 3
> Pl. Eusebi Güell, 6
> 08034 - Barcelona


-- 
Adrian Klaver
adrian.klaver@gmail.com


-- 
Sent via pgsql-sql mailing list (pgsql-sql@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-sql



^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2013-03-21 13:40 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2013-03-21 11:43 Reading from file without superuser privilege Jose Antonio Quintana/UPC <jose.antonio.quintana@upc.edu>
2013-03-21 13:40 ` Adrian Klaver <adrian.klaver@gmail.com>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox